Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,753
Quick preset (or use dates below)
Clear Filters
Showing 1,761 - 1,780 of 13,434 CVEs
CVE-2026-1871 MEDIUM - 6.5

TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core service process to cra...

Vendor: tp-link
Product: tapo_c200_firmware
Published: Jun 02, 2026
Source: NVD
CVE-2026-9590 MEDIUM - 5.3

Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.

Vendor: devolutions
Product: devolutions_server
Published: Jun 02, 2026
Source: NVD
CVE-2026-9522 MEDIUM - 5.4

Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations.

Vendor: devolutions
Product: devolutions_server
Published: Jun 02, 2026
Source: NVD
CVE-2026-7299 MEDIUM - 6.3

Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a malicious table or column names triggering arbitrary code execution in the sessions of other workspac...

Vendor: appsmith
Product: appsmith
Published: Jun 02, 2026
Source: NVD
CVE-2026-38978 MEDIUM - 5.3

transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.

Published: Jun 02, 2026
Source: NVD
CVE-2026-35718 MEDIUM - 6.5

A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via sending a crafted request.

Vendor: vivotek
Product: fd8136_firmware
Published: Jun 02, 2026
Source: NVD
CVE-2026-35716 MEDIUM - 6.3

A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an oversized n1 parameter in a POST request to the /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, or /cgi-bin/a...

Vendor: vivotek
Product: fd8136_firmware
Published: Jun 02, 2026
Source: NVD
CVE-2026-34460 MEDIUM - 5.4

NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not validate the state parameter server-side before exchanging the authorization code. This allows an attacker to capture a valid OAuth callback URL for their own account and cause a v...

Vendor: NamelessMC
Product: Nameless
Published: Jun 02, 2026
Source: NVD
CVE-2026-49782 MEDIUM - 5.4

Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elementor Website Builder: from n/a through 4.1.0.

Vendor: Elementor
Product: Elementor Website Builder
Published: Jun 02, 2026
Source: NVD
CVE-2026-41918 MEDIUM - 5.7

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This could allow an authenticated attacker to access sensitive da...

Vendor: Siemens
Product: RUGGEDCOM RST2428P
Published: Jun 02, 2026
Source: NVD
CVE-2026-35717 MEDIUM - 6.3

A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controll...

Vendor: vivotek
Product: fd8136_firmware
Published: Jun 02, 2026
Source: NVD
CVE-2026-32250 MEDIUM - 4.3

NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in version 2.2.4 in the id parameter of the endpoint `/index.php?route=/queries/user/`. The application reflects user-supplied input from the id parameter into the HTML response ...

Vendor: NamelessMC
Product: Nameless
Published: Jun 02, 2026
Source: NVD
CVE-2026-28116 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Progress Planner allows Stored XSS. This issue affects Progress Planner: from n/a through 1.9.0.

Vendor: Emilia Projects
Product: Progress Planner
Published: Jun 02, 2026
Source: NVD
CVE-2026-27351 MEDIUM - 5.4

Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Crew HRM: from n/a through 1.2.2.

Vendor: Sekander Badsha
Product: Crew HRM
Published: Jun 02, 2026
Source: NVD
CVE-2019-25717 MEDIUM - 4.3

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration deta...

Vendor: Dräger
Product: Infinity Delta, Infinity Delta XL, Infinity Kappa
Published: Jun 02, 2026
Source: NVD
CVE-2026-8993 MEDIUM - 6.5

D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side R...

Published: Jun 02, 2026
Source: NVD
CVE-2026-5422 MEDIUM - 6.8

A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check uses startswith(root) without appending a trailing path separator, allowing sibling dir...

Vendor: jupyter
Product: jupyter_server
Published: Jun 02, 2026
Source: NVD
CVE-2026-5191 MEDIUM - 5.4

The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'data-image-title' parameter in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...

Published: Jun 02, 2026
Source: NVD
CVE-2026-46718 MEDIUM - 6.5

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcite: from 1.5.0 before 1.42. Users are recommended to upgrade to version 1.42, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Calcite
Published: Jun 02, 2026
Source: NVD
CVE-2026-41115 MEDIUM - 4.3

An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka documentation and the KIP-848. This disc...

Vendor: Apache Software Foundation
Product: Apache Kafka
Published: Jun 02, 2026
Source: NVD